PT-2026-3422 · Itsourcecode · Society Management System
Tehs
·
Publicado
2026-01-19
·
Atualizado
2026-01-19
·
CVE-2026-1135
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
itsourcecode Society Management System version 1.0
Description
A security flaw exists in itsourcecode Society Management System 1.0. The manipulation of the
Title argument in the file '/admin/activity.php' can lead to cross site scripting. This attack can be launched remotely. The exploit has been publicly released.Recommendations
Apply any available updates or patches for itsourcecode Society Management System version 1.0.
As a temporary workaround, consider restricting access to the file '/admin/activity.php'.
Sanitize the
Title argument to prevent the injection of malicious scripts.Exploit
Correção
XSS
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Society Management System